RHBA-2024:5865MediumCVSS 6.0
Red Hat Bug Fix Advisory: Custom Metrics Autoscaler Operator for Red Hat 2.14.1-454 OpenShift Bug Fixes
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-6104 — go-retryablehttp: url might write sensitive information to log file
🎯 Affected products6
- OpenShift Custom Metrics Autoscaler 2
- custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel8@sha256:d05da8651c9467ffbe11090a49bea1f87095615eb8145314cfd571f3e6cb206e_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
- custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel8@sha256:b4ff63e81ac39f8ea9f2e9771ab0f221f6d76a58446fe8fe10889552fdbcd4f0_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
- custom-metrics-autoscaler/custom-metrics-autoscaler-operator-bundle@sha256:d558d65a0a5d3439775b18d74cd017a9d5b68dd523eb965c479d1a8b87b2516d_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
- custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8-operator@sha256:7d09f9e9ddc07a730ef6d25fe8b4a6f0482b8f4b0a15b58e9396c414d3a95711_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
- custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8@sha256:5d4878a03286086335309b6dec3165b2538da56d0adf1ef533970fcf3a4f9bca_amd64 as a component of OpenShift Custom Metrics Autoscaler 2
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.